Hewlett Packard Enterprise (HPE) has released security updates to address critical remote code execution (RCE) vulnerabilities within its ArubaOS-CX operating system. The vulnerabilities, collectively tracked under CVE-2026-73749, carry a high CVSS score of 9.8, indicating a severe risk.

Hewlett Packard Enterprise (HPE) has issued security updates to mitigate critical remote code execution (RCE) vulnerabilities identified in its ArubaOS-CX operating system. These vulnerabilities, which have been assigned the identifier CVE-2026-73749, pose a significant risk, as reflected by their CVSS score of 9.8.
The vulnerabilities specifically impact the ArubaOS-CX operating system, which is utilized across a range of HPE Aruba networking products. While the specific technical mechanisms leading to RCE were not detailed, such flaws typically involve issues like improper input validation, buffer overflows, or authentication bypasses in network-facing services. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code on the affected device with elevated privileges.
Remote code execution vulnerabilities are particularly severe because they often enable attackers to gain complete control over a compromised system without requiring prior access or user interaction. In the context of network operating systems, this could lead to the ability to manipulate network traffic, disable security controls, or establish persistent access within an enterprise network infrastructure.
The scope of affected products would include any HPE Aruba networking devices running the vulnerable versions of ArubaOS-CX. Organizations deploying these switches and other network infrastructure components are advised to consult HPE's official security advisories for a definitive list of impacted models and software versions.
Mitigation for RCE vulnerabilities typically involves applying vendor-provided patches as soon as they become available. In cases where immediate patching is not feasible, organizations might consider temporary workarounds such as restricting access to affected services, deploying network segmentation, or implementing strict firewall rules to limit exposure to untrusted networks. However, these are generally temporary measures and do not replace the need for applying the official security updates.
The discovery and patching of critical RCE vulnerabilities in network operating systems underscore the ongoing importance of robust security practices in enterprise networking. Such flaws highlight the need for continuous vulnerability management, prompt patching cycles, and defense-in-depth strategies to protect critical infrastructure from sophisticated threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed